Malware

Bulz.60466 removal guide

Malware Removal

The Bulz.60466 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.60466 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (13 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
assets.onestore.ms
statics-marketingsites-wcus-ms-com.akamaized.net
ajax.aspnetcdn.com
mem.gfx.ms
js.monitor.azure.com
smplus-prod-frontdoor.azurefd.net
ocsp.digicert.com
cacerts.digicert.com
img-prod-cms-rt-microsoft-com.akamaized.net

How to determine Bulz.60466?


File Info:

crc32: 3BD7DC8D
md5: 067c4e46aaa2207a9035053331b76d38
name: 067C4E46AAA2207A9035053331B76D38.mlw
sha1: ab69ee698162878991e6f1b0e93f053579f29296
sha256: e52705386ad0dbcca9861d422254d4910ae15e3d475bbaf573bb28887d220482
sha512: 1daae433d0be1df627b51ab0c2a70a99575e9351466702db57b7fd874475a1c44fb157d29797c37e3cc1053f8c16b838610dccd3e79192e0cad54e502d024076
ssdeep: 24576:z7blIar6REw7uxHYn/tkdyyPnpo5lzjB1oxq67aRq8Imj4Y3:z75/mEAem/t7Snpo5lzj6p+sm8Y3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Nate Woolls
Comments: This installation was built with Inno Setup.
ProductName: MultiMiner
ProductVersion: 4.3.0
FileDescription: MultiMiner Setup
Translation: 0x0000 0x04b0

Bulz.60466 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusUnwanted-Program ( 004bf75d1 )
LionicTrojan.Win32.MultiMiner.4!c
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.60466
CylanceUnsafe
SangforCoinMiner.Win32.Agent.mt
AlibabaTrojan:Win32/CoinMiner.e60030dd
K7GWUnwanted-Program ( 004bf75d1 )
Cybereasonmalicious.6aaa22
CyrenW32/Application.LHYR-8115
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/MultiMiner.B potentially unsafe
APEXMalicious
AvastWin32:MultiMiner-E [Miner]
KasperskyHEUR:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Bulz.60466
NANO-AntivirusTrojan.Win32.MultiMiner.iupehy
MicroWorld-eScanGen:Variant.Bulz.60466
TencentWin32.Trojan.Coinminer.Eym
SophosMultiMiner (PUA)
ComodoMalware@#3aipt068b495j
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
FireEyeGen:Variant.Bulz.60466
EmsisoftGen:Variant.Bulz.60466 (B)
WebrootW32.Trojan.Miner
AviraPUA/CoinMiner.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2FEA1D3
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPUA:Win32/CoinMiner
GridinsoftTrojan.Win32.CoinMiner.dd!n
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
GDataMSIL.Application.CoinMiner.V@gen (4x)
McAfeeArtemis!067C4E46AAA2
MAXmalware (ai score=83)
VBA32Trojan.CoinMiner
PandaTrj/CI.A
MaxSecureTrojan.Malware.102607949.susgen
FortinetAdware/MultiMiner
AVGWin32:MultiMiner-E [Miner]
Paloaltogeneric.ml
Qihoo-360Win32/Miner.Coinminer.HgIASOoA

How to remove Bulz.60466?

Bulz.60466 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment